Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares sensitive capabilities in metadata (`env`, workspace files) and also clearly uses network access, file writes, and local execution, but it lacks an explicit permissions model governing those actions. That mismatch makes review and enforcement weaker, increasing the chance that the skill can access credentials, write persistent state, and contact external services without clear operator consent.
